Vulnerability Description
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gstreamer | Gstreamer | - |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-12891Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2491318Third Party Advisory
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5109Not Applicable
FAQ
What is CVE-2026-12891?
CVE-2026-12891 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds re...
How severe is CVE-2026-12891?
CVE-2026-12891 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12891?
Check the references section above for vendor advisories and patch information. Affected products include: Gstreamer Gstreamer, Redhat Enterprise Linux.